top | item 46428226

(no title)

computerfan494 | 2 months ago

That's a good question. I suppose that posting the commit makes it incredibly obvious how to exploit the issue, so maybe they wanted to wait a little bit longer for their on-prem users who were slow to patch?

discuss

order

philipwhiuk|2 months ago

Posting the CVE and then the patch is the reverse of this.

computerfan494|2 months ago

By "patch" I am talking about the public commit. Updated binaries were made available when the CVE was published.