GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
{ "versions": [ { "introduced": "8.14.0" }, { "fixed": "12.3.8" }, { "introduced": "12.4.0" }, { "fixed": "12.4.5" }, { "introduced": "12.5.0" }, { "fixed": "12.5.2" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19312.json"