An IDOR was discovered in GitLab CE/EE 11.5 and later that allowed new merge requests endpoint to disclose label names.
{ "versions": [ { "introduced": "11.5.0" }, { "fixed": "11.11.7" }, { "introduced": "11.5.0" }, { "fixed": "11.11.7" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5466.json"