14.5.4 TODO

Verify that HTTP headers added by a trusted proxy or SSO devices, such as a bearer token, are authenticated by the application.

Level 1  
Level 2 X
Level 3 X
CWE NIST
306