In my experience self-hosted GitLabs are rarely publicly-accessible in the first place; they're usually behind some sort of VPN.
As for an attacker being able to iterate through users, if that information is supposed to be private, and yet an attacker is getting anything other than a 404, then that's a problem in and of itself and my energy would be better spent fixing that.