A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos
https://gitlab.com/gitlab-org/gitlab/-/issues/215175
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13323.json