Aaron Patterson of Red Hat reports: There are a number of locations in the code where .to_sym is called on user supplied code, resulting in a potential DoS condition as an attacker can insert symbols that are never garbage collected.
Acknowledgement: This issue was discovered by Aaron Patterson of the Red CloudForms Team.
Statement: This issue affects the versions of cfme as shipped with Red Hat CloudForms 3. Red Hat Product Security has rated this issue as having Low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.