Your judgment seems rather harsh. Pre-existing anti-Red Hat bias? The Fedora project is
actually one of the more openly-run community Linux distributions -- apart from Debian, I'm
hard-pressed to name another project that is as open to community input (and in fact, it is
easier to become a Fedora contributor than to be a Debian developer).
As others have said, this is probably a Fedora-specific vulnerability. If it affects no other
service providers, and Fedora has warned its users not to use their services from the time
being, how is a full disclosure the more responsible thing to do? You'd be providing more
information about possible attack vectors, without any legitimate use.
Disclaimer: I am a Fedora contributor myself