Old API versions can preserve old weaknesses

Fixing something in the current version does not fix it in the one still running beside it.

The flaw was patched, the release notes say so, and the old endpoint retains the original behaviour because nobody wanted to break existing consumers. An attacker will simply call the older version, which is why deprecation has to end in removal rather than in discouragement.

More on API security