4 ms·
That's a good question. I suppose that posting the commit makes it incredibly obvious how to exploit the issue, so maybe they wanted to wait a little bit longer
by computerfan494 9mo ago
That's a good question. I suppose that posting the commit makes it incredibly obvious how to exploit the issue, so maybe they wanted to wait a little bit longer for their on-prem users who were slow to patch?
- philipwhiuk 9mo agoPosting the CVE and then the patch is the reverse of this.
- computerfan494 9mo agoBy "patch" I am talking about the public commit. Updated binaries were made available when the CVE was published.
- philipwhiuk 9mo agoThat's not what the blog post implies given they only told people how to update aftwards.