A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the private activity of a user could be exposed via the API.
https://gitlab.com/gitlab-org/gitlab/-/issues/24542
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13324.json