As @lukastribus says, proceed with care. These are headers you need to set correctly to avoid confusing breakage.
*[Since we don’t know what you have behind your proxy or how relevant the pen test finding is for your environment, we can’t eliminate the possibility that the proxy is the best place to inject headers.]