A SAML2 multi-session flaw was found in ipsilon 2.0.0. External references: https://ipsilon-project.org/release/2.1.0.html
*** This bug has been marked as a duplicate of bug 1392829 ***
Some background on marking duplicate: Between Ipsilon 2.0.1 and 2.0.0, CVE-2016-8638 had been found and fixed, with multiple releases to fix it, but the entry did again show up in the 2.1.0 release notes because that's on a different branch. Someone found that entry in our changelog and requested a CVE ID from Mitre and got assigned CVE-2017-16855. But this was just the fix on the master branch that was already released as 2.0.2 (among other backport releases) of CVE-2016-8638.