Internet2 develops identity and access management infrastructure for research and education institutions, with a primary focus on federated authentication and group management through products such as OpenSAML, Shibboleth Service Provider, and Grouper. The vendor's vulnerabilities cluster around input-handling and authorization weaknesses—including cross-site scripting, sensitive information exposure, memory-safety issues, and improper access control—reflecting the web-facing and trust-boundary complexity inherent to identity middleware. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Internet2 over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-3476HIGH Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth S | Sep 29, 2009 | 9.3 | 27 | NO | NO |
CVE-2018-19794MEDIUM Cross-site scripting (XSS) vulnerability in UiV2Public.index in Internet2 Grouper 2.2 and 2.3 allows remote attackers to inject arbitrary web script or HTML via the code parameter. | Dec 3, 2018 | 6.1 | 21 | NO | NO |
CVE-2009-3475HIGH Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a '\0' character in the subject o | Sep 29, 2009 | 7.5 | 21 | NO | NO |
CVE-2009-3474HIGH OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDescriptor element's Use attribut | Sep 29, 2009 | 7.5 | 21 | NO | NO |
CVE-2025-59714MEDIUM In Internet2 Grouper 5.17.1 before 5.20.5, group admins who are not Grouper sysadmins can configure loader jobs. | Sep 19, 2025 | 4.9 | 18 | NO | NO |
CVE-2013-6440MEDIUM The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to tr | Feb 14, 2014 | 5.0 | 16 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1.5, and the Service Provider 1.3.x before 1.3.5 and 2.x befo | Nov 6, 2009 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Internet2.
Media articles that mention a CVE ID that affects a product developed by Internet2 — matched by CVE ID, not by vendor name.