GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 has Incorrect Access Control. After a project changed to private, previously forked repositories were still able to get information about the private project through the API.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-19312.json"