An issue was discovered in GitLab Community and Enterprise Edition 12.0 through 12.2.1. Non-members were able to comment on merge requests despite the repository being set to allow only project members to do so.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-15731.json"