Aaron Patterson of Red Hat reports:
There are a number of locations in the code where .to_sym is called on user
supplied code, resulting in a potential DoS condition as an attacker can
insert symbols that are never garbage collected.
Statement:
This issue affects the versions of cfme as shipped with Red Hat CloudForms 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.