Red Hat Ansible Automation Platform 2.5
Red Hat Ansible Automation Platform 2.5
Third-party support for the Red Hat Ansible Automation Platform 2.5: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance — independent of the vendor contract.
24/7 engineers own your Red Hat Ansible Automation Platform 2.5 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- red-hat-ansible-automation-platform
- release
- 2.5
- product Label
- Red Hat Ansible Automation Platform
- release Label
- 2.5
- codename
- lts
- latest Version
- release Date
- 2024-09-30
- maintained
- true
- source Url
- https://endoflife.date/red-hat-ansible-automation-platform
Lifecycle Dates
- End of Service Life
- Oct 2, 2027
- Last OEM Support
- Oct 2, 2025
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Red Hat Ansible Automation Platform 2.5 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Red Hat Ansible Automation Platform 2.5?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Red Hat Ansible Automation Platform 2.5 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Red Hat Ansible Automation Platform 2.5 Support: Frequently Asked Questions
Is the Red Hat Ansible Automation Platform 2.5 still supported?
Yes. The Red Hat Ansible Automation Platform 2.5 is currently supported by Red Hat Ansible Automation Platform, and third-party support is available as an alternative — issue management, vulnerability remediation, and compliance help independent of the vendor contract.
When is the Red Hat Ansible Automation Platform 2.5 end of service life (EOSL) date?
Red Hat Ansible Automation Platform lists the end of service life for the Red Hat Ansible Automation Platform 2.5 as Oct 2, 2027.
Can I keep using the Red Hat Ansible Automation Platform 2.5 after its EOSL date?
Yes. EOSL means Red Hat Ansible Automation Platform stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Red Hat Ansible Automation Platform 2.5 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Red Hat Ansible Automation Platform 2.5
5 published CVEs affect the Red Hat Ansible Automation Platform 2.5. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2025-9909 | MEDIUM | 6.7 | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked. |
| CVE-2025-9908 | MEDIUM | 6.7 | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By exfiltrating these headers, an attacker could spoof trusted requests, escalate privileges, or perform malicious event injection. |
| CVE-2025-9907 | MEDIUM | 6.7 | Feb 27, 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to al |
| CVE-2025-57847 | MEDIUM | 6.4 | Apr 8, 2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID |
| CVE-2024-10033 | MEDIUM | 6.1 | Oct 16, 2024 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data. |