une faille permettait d'acc\u00e9der aux courriers personnels des assur\u00e9s<\/title>\n<meta name=\"description\" content=\"En modifiant simplement un chiffre dans l'URL, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s. La faille a \u00e9t\u00e9 corrig\u00e9e.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Assurance maladie : une faille permettait d'acc\u00e9der aux courriers personnels des assur\u00e9s\" \/>\n<meta property=\"og:description\" content=\"En modifiant simplement un chiffre dans l'URL, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s. La faille a \u00e9t\u00e9 corrig\u00e9e.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\" \/>\n<meta property=\"og:site_name\" content=\"PhonAndroid\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/phonandroid\" \/>\n<meta property=\"article:published_time\" content=\"2019-12-20T08:00:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wp-pa.phonandroid.com\/uploads\/2019\/12\/assurance-maladie-faille-ameli.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"840\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kevin Dachez\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:site\" content=\"@phonandroid\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kevin Dachez\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\"},\"author\":{\"name\":\"Kevin Dachez\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc\"},\"headline\":\"Assurance maladie : une faille permettait d’acc\u00e9der aux courriers personnels des assur\u00e9s\",\"datePublished\":\"2019-12-20T08:00:04+00:00\",\"dateModified\":\"2019-12-20T08:00:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\"},\"wordCount\":493,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"articleSection\":[\"Actualit\u00e9s\"],\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#respond\"]}],\"copyrightYear\":\"2019\",\"copyrightHolder\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\",\"url\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\",\"name\":\"Assurance maladie : une faille permettait d'acc\u00e9der aux courriers personnels des assur\u00e9s\",\"isPartOf\":{\"@id\":\"https:\/\/www.phonandroid.com\/#website\"},\"datePublished\":\"2019-12-20T08:00:04+00:00\",\"dateModified\":\"2019-12-20T08:00:04+00:00\",\"description\":\"En modifiant simplement un chiffre dans l'URL, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s. La faille a \u00e9t\u00e9 corrig\u00e9e.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.phonandroid.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Assurance maladie : une faille permettait d’acc\u00e9der aux courriers personnels des assur\u00e9s\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.phonandroid.com\/#website\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"name\":\"PhonAndroid\",\"description\":\"PhonAndroid\",\"publisher\":{\"@id\":\"https:\/\/www.phonandroid.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.phonandroid.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.phonandroid.com\/#organization\",\"name\":\"PhonAndroid\",\"url\":\"https:\/\/www.phonandroid.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png\",\"contentUrl\":\"https:\/\/img.phonandroid.com\/2023\/06\/dark.png\",\"width\":280,\"height\":60,\"caption\":\"PhonAndroid\"},\"image\":{\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/phonandroid\",\"https:\/\/twitter.com\/phonandroid\",\"https:\/\/www.youtube.com\/user\/Phonandroidtv\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc\",\"name\":\"Kevin Dachez\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g\",\"caption\":\"Kevin Dachez\"},\"description\":\"Chef de rubrique Mobilit\u00e9 urbaine et voitures \u00e9lectriques. Entre deux actualit\u00e9s sur les derniers mod\u00e8les watt\u00e9s, j'\u00e9cris \u00e9galement sur mon autre passion : les jeux vid\u00e9o. Remedy, ne ratez pas Alan Wake 2 s'il vous pla\u00eet.\",\"url\":\"https:\/\/www.phonandroid.com\/author\/kdachez\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Assurance maladie : une faille permettait d'acc\u00e9der aux courriers personnels des assur\u00e9s","description":"En modifiant simplement un chiffre dans l'URL, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s. La faille a \u00e9t\u00e9 corrig\u00e9e.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html","og_locale":"fr_FR","og_type":"article","og_title":"Assurance maladie : une faille permettait d'acc\u00e9der aux courriers personnels des assur\u00e9s","og_description":"En modifiant simplement un chiffre dans l'URL, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s. La faille a \u00e9t\u00e9 corrig\u00e9e.","og_url":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html","og_site_name":"PhonAndroid","article_publisher":"https:\/\/www.facebook.com\/phonandroid","article_published_time":"2019-12-20T08:00:04+00:00","og_image":[{"width":840,"height":525,"url":"https:\/\/wp-pa.phonandroid.com\/uploads\/2019\/12\/assurance-maladie-faille-ameli.jpg","type":"image\/jpeg"}],"author":"Kevin Dachez","twitter_card":"summary_large_image","twitter_creator":"@phonandroid","twitter_site":"@phonandroid","twitter_misc":{"Written by":"Kevin Dachez","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#article","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html"},"author":{"name":"Kevin Dachez","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc"},"headline":"Assurance maladie : une faille permettait d’acc\u00e9der aux courriers personnels des assur\u00e9s","datePublished":"2019-12-20T08:00:04+00:00","dateModified":"2019-12-20T08:00:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html"},"wordCount":493,"commentCount":0,"publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"articleSection":["Actualit\u00e9s"],"inLanguage":"fr-FR","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#respond"]}],"copyrightYear":"2019","copyrightHolder":{"@id":"https:\/\/www.phonandroid.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html","url":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html","name":"Assurance maladie : une faille permettait d'acc\u00e9der aux courriers personnels des assur\u00e9s","isPartOf":{"@id":"https:\/\/www.phonandroid.com\/#website"},"datePublished":"2019-12-20T08:00:04+00:00","dateModified":"2019-12-20T08:00:04+00:00","description":"En modifiant simplement un chiffre dans l'URL, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s. La faille a \u00e9t\u00e9 corrig\u00e9e.","breadcrumb":{"@id":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.phonandroid.com\/"},{"@type":"ListItem","position":2,"name":"Assurance maladie : une faille permettait d’acc\u00e9der aux courriers personnels des assur\u00e9s"}]},{"@type":"WebSite","@id":"https:\/\/www.phonandroid.com\/#website","url":"https:\/\/www.phonandroid.com\/","name":"PhonAndroid","description":"PhonAndroid","publisher":{"@id":"https:\/\/www.phonandroid.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.phonandroid.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/www.phonandroid.com\/#organization","name":"PhonAndroid","url":"https:\/\/www.phonandroid.com\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.phonandroid.com\/wp-content\/themes\/phonadroid-v3\/assets\/images\/lg-phonandroid-amp-4.png","contentUrl":"https:\/\/img.phonandroid.com\/2023\/06\/dark.png","width":280,"height":60,"caption":"PhonAndroid"},"image":{"@id":"https:\/\/www.phonandroid.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/phonandroid","https:\/\/twitter.com\/phonandroid","https:\/\/www.youtube.com\/user\/Phonandroidtv"]},{"@type":"Person","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/3001e437c542c9695c28fcfcf4e69afc","name":"Kevin Dachez","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/www.phonandroid.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/520860d02bb9f0366d858dd41b27739e?s=96&d=mm&r=g","caption":"Kevin Dachez"},"description":"Chef de rubrique Mobilit\u00e9 urbaine et voitures \u00e9lectriques. Entre deux actualit\u00e9s sur les derniers mod\u00e8les watt\u00e9s, j'\u00e9cris \u00e9galement sur mon autre passion : les jeux vid\u00e9o. Remedy, ne ratez pas Alan Wake 2 s'il vous pla\u00eet.","url":"https:\/\/www.phonandroid.com\/author\/kdachez"}]}},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2268493","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/users\/110"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/comments?post=2268493"}],"version-history":[{"count":0,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/posts\/2268493\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media\/2268496"}],"wp:attachment":[{"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/media?parent=2268493"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/categories?post=2268493"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phonandroid.com\/wp-json\/wp\/v2\/tags?post=2268493"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}

{"id":2268493,"date":"2019-12-20T09:00:04","date_gmt":"2019-12-20T08:00:04","guid":{"rendered":"https:\/\/www.phonandroid.com\/?p=2268493"},"modified":"2019-12-20T09:00:04","modified_gmt":"2019-12-20T08:00:04","slug":"assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures","status":"publish","type":"post","link":"https:\/\/www.phonandroid.com\/assurance-maladie-une-faille-permettait-dacceder-aux-courriers-personnels-des-assures.html","title":{"rendered":"Assurance maladie : une faille permettait d’acc\u00e9der aux courriers personnels des assur\u00e9s"},"content":{"rendered":"

Le site de l'Assurance Maladie, Ameli.fr, \u00e9tait victime d'une faille de s\u00e9curit\u00e9 embarrassante. Gr\u00e2ce \u00e0 cette br\u00e8che, n'importe quel assur\u00e9 pouvait acc\u00e9der aux messages personnels d'autres assur\u00e9s en modifiant simplement un chiffre dans l'URL. Ces messages contiennent de nombreuses donn\u00e9es personnelles, comme des noms, pr\u00e9noms, adresses ou encore des num\u00e9ros de s\u00e9curit\u00e9 sociale. La faille a \u00e9t\u00e9 “imm\u00e9diatement corrig\u00e9e”.\u00a0<\/strong><\/p>\n

\"fond<\/p>\n

Une faille de s\u00e9curit\u00e9 importante a \u00e9t\u00e9 rep\u00e9r\u00e9e le jeudi 19 d\u00e9cembre 2019 sur Ameli.fr, le portail en ligne de la Caisse nationale de l'Assurance Maladie (CPAM). C'est en tout cas que ce nous r\u00e9v\u00e8lent nos confr\u00e8res du site sp\u00e9cialis\u00e9 NextInpact, qui ont \u00e9t\u00e9 alert\u00e9s par un lecteur averti. Cette br\u00e8che permettait vraisemblablement \u00e0 n'importe quel assur\u00e9 de pouvoir acc\u00e9der aux messages personnels d'autres assur\u00e9s, en modifiant simplement un chiffre dans l'URL.<\/p>\n

Il s'av\u00e8re que les messages \u00e0 destination des assur\u00e9s sont stock\u00e9s en format PDF sur leur espace personnel du site Ameli.fr. De fait, en modifiant un chiffre dans l'URL, il \u00e9tait possible de tomber sur les correspondances de n'importe quel assur\u00e9 au hasard. Or, ces messages contiennent un bon nombre de donn\u00e9es personnelles : nom, pr\u00e9nom, adresse mail et du domicile, num\u00e9ros de s\u00e9curit\u00e9 sociale, les diff\u00e9rentes demandes de renseignements, de prise en charge, les refus de soins, etc.<\/p>\n

\u00c0 lire \u00e9galement : La carte vitale d\u00e9barque sur smartphone d\u00e8s 2021<\/a><\/strong><\/p>\n