And more specifically (as it was the reason for seeking clarity on those questions), since neither fixing this feature nor removing it is going to solve any real-world security vulnerability (only possibly addressing compliance impedance mismatches), I don't believe there's any benefit to our users in keeping this bug report embargoed. I think we should change it to public and bring the OSSG in on notifying the community if they see fit.
And more specifically (as it was the reason for seeking clarity on those questions), since neither fixing this feature nor removing it is going to solve any real-world security vulnerability (only possibly addressing compliance impedance mismatches), I don't believe there's any benefit to our users in keeping this bug report embargoed. I think we should change it to public and bring the OSSG in on notifying the community if they see fit.