I assume that they didn't want to call attention to the fix before users had time to update. (Don't want to create a race between attackers and defenders)
But now that the this vulnerability is being announced, how do I find out what code or API endpoint was vulnerable?
EDIT: I mean, just the diff between the offending lines of code and the corrected ones. I assume this vulnerability isn't obvious. It hung around for 6 years. And the commit message probably didn't point it out explicitly, because they didn't want to disclose prior to building the release.
If I just diff everything that changed, I'll probably not be able to point and say, "Oh yeah, that line is bad"