Might not be how it appears. The CVE number can be reserved by the org and then "published" with only minimal info, then later update with full details. Looking at the meta data that's probably what happened here (not entirely sure what the update was though):
That's a good question. I suppose that posting the commit makes it incredibly obvious how to exploit the issue, so maybe they wanted to wait a little bit longer for their on-prem users who were slow to patch?
joecool1029|2 months ago
theteapot|2 months ago
cebert|2 months ago
tanduv|2 months ago
computerfan494|2 months ago
philipwhiuk|2 months ago