Overview

FieldValue
ID1063
NameManage ArgoCD Applications (argoproj.io)
Risk CategoryTampering
Risk LevelCritical
Role TypeRole
API Groupsargoproj.io
Resourcesapplications
Verbscreate, update, patch, delete, sync
TagsCodeExecution PotentialPrivilegeEscalation Tampering WorkloadDeployment

Description

Grants permission to manage ArgoCD Application resources. This allows deploying, modifying, or deleting applications managed by ArgoCD, potentially leading to the deployment of malicious workloads, unauthorized code execution, tampering with production systems, and privilege escalation if ArgoCD has high privileges.