I'm pretty sure that this bug has been around substantially forever, so we should probably put Affects: <=7.0.0
Now that I understand the process a little better from comment #23, I think I'm saying that this is IMHO not severe enough to require an embargo. If waiting for a CVE is not appropriate then I'd be fine with flipping this to public now and just committing the patch (which is ready to go).
I'm pretty sure that this bug has been around substantially forever, so we should probably put Affects: <=7.0.0
Now that I understand the process a little better from comment #23, I think I'm saying that this is IMHO not severe enough to require an embargo. If waiting for a CVE is not appropriate then I'd be fine with flipping this to public now and just committing the patch (which is ready to go).