The web application is prone to a user enumeration vulnerability

In short, when you open the {gitlab_url}/search page, you can run a search even without authorization. If you type “nov” in the search box (most of the surnames have these characters), you can see user names.