This is about as serious as the CSS exploit that allowed detection of which websites you'd visited. In a way it is more serious because it allows the attacker to detect a relationship on a higher level (logged in versus merely visited).
http://lists.w3.org/Archives/Public/public-webappsec/2014Feb...
[1] https://grepular.com/Abusing_HTTP_Status_Codes_to_Expose_Pri...