Membership changes are not reflected in ToDo subscriptions in GitLab versions prior to 13.2.10, 13.3.7 and 13.4.2, allowing guest users to access confidential issues through API.
https://hackerone.com/reports/880863
https://gitlab.com/gitlab-org/gitlab/-/issues/219496
https://gitlab.com/gitlab-org/cves/-/blob/master/2020/CVE-2020-13346.json