An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.0.2. Unauthorized users were able to read pipeline information of the last merge request. It has Incorrect Access Control.
{ "versions": [ { "introduced": "11.10.0" }, { "last_affected": "12.0.2" }, { "introduced": "11.10.0" }, { "last_affected": "12.0.2" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13002.json"