I think the point being made here is why are both numbers not disclosed, and only one was?
I think both the time the bug existed and the relevant timeframe of known exploits should be part of a responsible security disclosure.
Omitting either one is a disservice to users.