When replying to a private comment, the new comment doesn't get flagged "private" as well. When I stumbled over it -- while adding https://bugzilla.redhat.com/show_bug.cgi?id=438028#c13 -- no harm was done, but this still is a potential information leak.
Red Hat Bugzilla is now using version 3.2 of the Bugzilla codebase and therefore this bug will need to be re-verified against the new release. With the updated code this bug may no longer be relevant or may have been fixed in the new code. Updating bug version to 3.2.
This seems to work now, thanks!