In GitLab EE 11.3 through 12.5.3, 12.4.5, and 12.3.8, insufficient parameter sanitization for the Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-19628.json"