Jan Rusnacko of Red Hat reports:
Katello code exposes potential to_sym Denial of Service attack vector from user input parameters. The two places identified are:
This type of attack is documented here - http://docs.fedoraproject.org/en-US/Fedora_Security_Team/1/html/Secure_Ruby_Development_Guide/RubySymbols.html
This has been confirmed in testing by Eric Helms of Red Hat.
*** Bug 1153824 has been marked as a duplicate of this bug. ***
This issue was discovered by Jan Rusnacko of Red Hat Product Security.
Created redmine issue http://projects.theforeman.org/issues/8263 from this bug