We're about to do a long overdue upgrade. We've considered Jira 7.6 because of its Enterprise designation, and the reduced maintenance it would presumably require.
But, we would like to be sure that Jira 7.6 cannot be affected by the Diffie-Hellman vulnerability.
The research I've done indicates that the determining factor is not necessarily the Jira version, per se, but rather whether the Jira version uses Java version 8 -- because it can be configured to use 2048 bit-group as documented at Logjam (CVE-2015-4000) and Atlassian Products.
Can anyone recommend which Jira version to use, in light of our need to avoid the Diffie-Hellman vulnerability?