An improper access control vulnerability exists in GitLab <12.3.3 that allows an attacker to obtain container and dependency scanning reports through the merge request widget even though public pipelines were disabled.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-15591.json"