This vulnerability is basically an information disclosure issue that enables you to get BSSIDs from the Airport Utility without the appropriate location tracking entitlement. Even worse the OS will not even flash the "location being accessed" indicator in the status bar when geolocation is determined this way.
Essentially any app can shell out to the CLI tool and parse its output and then feed the resulting BSSID to one of the many external BSSID -> Geolocation services and determine a device's location.
At Kolide we are huge believers that device geolocation should not be accessible to third party programs without end-user prompting (even ones managed by MDM) so we aggressively seek out gaps the TCC authorization model (or other OS issues that undermine the tenets of https://honest.security) and report them whenever we find them.
I reported this vulnerability on January 17th 2020.
Edit: Btw, I am not really sure why the CVE was withdrawn. To me this is a pretty serious information disclosure style vulnerability and everyone should upgrade to this release as soon as possible.