Kibana, reverseproxy nginx and CORS enabled

Kibana passes a header called kbn-version for xsrf protection. Can you try adding that?

Details at https://github.com/elastic/kibana/pull/5587