mirror of
https://github.com/github/rails.git
synced 2026-01-09 14:48:01 -05:00
Before we were calling to_sym in the mime type, even when it is unknown what can cause denial of service since symbols are not removed by the garbage collector. Fixes: CVE-2014-0082