An issue was discovered in GitLab Community and Enterprise Edition 12.2 through 12.2.1. The project import API could be used to bypass project visibility restrictions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 31.4%