Red Hat Ansible Automation Platform

Red Hat Ansible Automation Platform 2.3

Red Hat Ansible Automation Platform 2.3

The Red Hat Ansible Automation Platform 2.3 reached end of service life on May 31, 2024 — Red Hat Ansible Automation Platform no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.

End of Service LifeEOSL Date: May 31, 2024
Issue Management

24/7 engineers own your Red Hat Ansible Automation Platform 2.3 incidents end to end.

Vulnerability Remediation

Mitigation and patch-around guidance when the vendor no longer ships fixes.

Compliance Maintenance

Controls evidence and documentation that keep auditors satisfied.

Specifications

product
red-hat-ansible-automation-platform
release
2.3
product Label
Red Hat Ansible Automation Platform
release Label
2.3
codename
lts
latest Version
release Date
2022-11-29
maintained
source Url
https://endoflife.date/red-hat-ansible-automation-platform

Lifecycle Dates

End of Service Life
May 31, 2024
Last OEM Support
Jun 30, 2023

Get Third Party Support

Your quote will be sent to this address.

By submitting this form, you agree to our Privacy Policy.

OEM vs. 3rd Party Support

See how third-party support compares to the vendor contract for Red Hat Ansible Automation Platform 2.3 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.

FeatureOEM Support3rd Party Support
Post-EOSL Support
Break/Fix Support
Until EOSL
24/7 Monitoring
Vulnerability Scanning & Remediation
Managed Operations
Procedure & Configuration Review
Compliance & Audit Documentation
Limited
Discounted Migration to Other Platforms

Why Choose 3rd Party Support for Red Hat Ansible Automation Platform 2.3?

Vulnerability Remediation

Scanning, mitigation and patch-around guidance for Red Hat Ansible Automation Platform 2.3 when the vendor no longer ships fixes.

Compliance Maintenance

Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.

24/7 Expert Support

Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.

Red Hat Ansible Automation Platform 2.3 Support: Frequently Asked Questions

Is the Red Hat Ansible Automation Platform 2.3 still supported?

Red Hat Ansible Automation Platform ended support for the Red Hat Ansible Automation Platform 2.3 on May 31, 2024 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.

When is the Red Hat Ansible Automation Platform 2.3 end of service life (EOSL) date?

Red Hat Ansible Automation Platform lists the end of service life for the Red Hat Ansible Automation Platform 2.3 as May 31, 2024.

Can I keep using the Red Hat Ansible Automation Platform 2.3 after its EOSL date?

Yes. EOSL means Red Hat Ansible Automation Platform stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.

How much does third-party support for the Red Hat Ansible Automation Platform 2.3 cost?

Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.

Known Vulnerabilities Affecting Red Hat Ansible Automation Platform 2.3

6 published CVEs affect the Red Hat Ansible Automation Platform 2.3, including 1 rated critical or high severity. Red Hat Ansible Automation Platform no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.

CVESeverityCVSSPublishedSummary
CVE-2023-3971HIGH7.3Oct 4, 2023An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise.
CVE-2025-9909MEDIUM6.7Feb 27, 2026A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.
CVE-2025-9908MEDIUM6.7Feb 27, 2026A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection.
CVE-2025-9907MEDIUM6.7Feb 27, 2026A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to al
CVE-2025-57847MEDIUM6.4Apr 8, 2026A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID
CVE-2023-5115MEDIUM6.3Dec 18, 2023An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Get Third Party Support

Related Red Hat Ansible Automation Platform Products

All Red Hat Ansible Automation Platform products →
Red Hat Ansible Automation Platform 2.3
Save 40-70% vs OEM
Get Third Party Support