I strongly disagree, this is 100% vulnerability, you're leaking private DNS records - aka if the name server is also used for private records these are effectively exposed.
There's NO REASON to have zone transfer enabled.
There's NO REASON to have zone transfer enabled.
There are absolutely reasons to have zone transfer enabled -- to transfer the zones from primary/authoritative DNS servers to secondary DNS servers.
Zone transfers should, however, be limited to just the secondary DNS servers and not open to the world.